Data Processing Agreement
Version 2026-08 (template). This DPA forms part of the Reseat Terms of Service between the customer (the controller) and [Operator legal entity] (the processor), and governs the processing of personal data the customer stores in its managed instance.
1. Subject matter and duration
The processor operates a dedicated ticket-resale operations instance on the controller’s behalf for the duration of the subscription, plus the post-termination grace and deletion period.
2. Nature and purpose of processing
Hosting, storage, backup, display, and automated processing (including AI-assisted parsing of forwarded confirmation emails) of the data the controller and its users enter, solely to provide the contracted service.
3. Categories of data and data subjects
- Data subjects: the controller’s staff; ticket buyers and counterparties of the controller’s resale activity.
- Data categories: contact and identity details, order and delivery details, purchase-account identifiers, financial transaction records. No special categories of data are intended to be processed.
4. Instructions
The processor processes personal data only on the controller’s documented instructions — the service configuration and in-app actions constitute those instructions — unless EU or member-state law requires otherwise, in which case the processor informs the controller before processing where permitted.
5. Confidentiality
Persons authorized to process the data are bound by confidentiality. Operator access to customer instances is limited to what fleet operation requires and is audit-logged.
6. Technical and organizational measures
- Single-tenant instances; no shared databases between customers.
- Access exclusively via private Tailscale network shares; no public exposure by default.
- Encryption in transit; encrypted off-site backups.
- Role-based access control and audit logging inside each instance.
- Capacity- and health-monitored fleet with security updates applied by the processor.
7. Sub-processors
The controller grants general authorization for the following sub-processors. The processor will announce additions or replacements in advance through the portal, giving the controller the right to object on reasonable data-protection grounds. Sub-processor DPAs are the standard self-serve agreements of each provider:
- [Hosting provider, e.g. Hetzner] — infrastructure hosting (EU).
- Tailscale Inc. — private networking / access layer.
- Anthropic — AI-assisted email parsing, where enabled by the controller.
- [Backup storage provider] — encrypted backup storage.
- Whop — billing and identity for the customer portal (account data only).
8. Assistance to the controller
The processor assists the controller with data-subject requests (the instance includes buyer-PII search and erasure tooling), and with security, breach-notification, and data-protection-impact obligations, taking into account the nature of processing.
9. Personal data breaches
The processor notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data, with the information reasonably available to support the controller’s own notification duties, and follows its documented breach runbook.
10. Return and deletion
On termination, the controller can export all data in standard formats during the grace period. Afterwards the processor deletes the instance, its volumes, and backups within the backup rotation window, unless law requires longer retention.
11. Audits
The processor makes available information necessary to demonstrate compliance with this DPA and allows audits by the controller or a mandated auditor, on reasonable notice, at most once per year unless a breach justifies more.
12. International transfers
Processing takes place in the EU where feasible. Where a sub-processor transfers data outside the EEA, transfers rely on adequacy decisions or standard contractual clauses as listed in that sub-processor’s DPA.